Critical severity9.8NVD Advisory· Published Oct 7, 2026
CVE-2026-62253
CVE-2026-62253
Description
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.
Affected products
1- Range: <11.0.283
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.